A 15-year-old kernel vulnerability present by default in Linux distributions allows locally authenticated users to gain full root control without special privileges or configurations.
A gap in Dialogflow CX made it possible to gain access to other chatbots within the same project through a compromised agent setup and exfiltrate user data or inject phishing messages.
Agent-driven GitHub workflows can be manipulated through crafted public issues to unauthorisedly disclose private repositories of the enterprise when the agent has organisation-wide read access.
Ransomware extortionists are exploiting insufficient access controls in Microsoft Defender (CVE-2026-33825) to obtain SYSTEM privileges and fully compromise systems.
Ransomware gangs exploit a vulnerability in Microsoft Defender to gain access to the SAM database through insufficient access controls and obtain SYSTEM privileges.
Ransomware gangs are exploiting the BlueHammer vulnerability in Microsoft Defender for privilege escalation, putting Windows systems at widespread risk.